Barco search

myBarco notifications

Unread

Read

You don't have any notifications.

Single sign-on: First time configuration with Azure as IDP

Article number: [1865] - Legacy code: [12608]

Applicable to

This is an example on setting up Barco Single sign-on with Microsoft Azure as your Identity Provider (IDP).

To find detailed steps using Barco Management Suite, see Quick start guide for Barco Single Sign-on.

OpenID Connect v1.0


  1. Navigate to Azure portal and search for the resource Azure Active Directory.
  2. On this page, under the Manage tab find and go to App Registrations → New registration.
    1. Enter any appropriate Name for this application for you to track it by.
    2. Under Supported account types, the API access selection may be left to default (Single Tenant).
    3. Under the Redirect URI, select platform as Web and past the Redirect URI and click on Register. You will now be navigated to the overview page for this new registration.
  3. Under Manage section, navigate to Certificates & secrets → New client secret.
    1. Add any Description for this new secret to track it by and set an Expiration period. Click on Add.
    2. Copy the newly added client secret Value and save it somewhere safe. This is accessible only once!

  4. Go to Overview, under the Essentials section and copy the Application (Client) ID and save it somewhere.
  5. Add Optional claims, only when either upn, given_name or family_name is not present in user properties by going to Token configuration (see Microsoft Docs).
  6. Navigate to the Single sign-on settings page on Barco Management Suite:
    1. Click on Add Configuration
    2. Enter a name for the configuration and select protocol as OpenID Connect v1.0
  7. Complete the form on the Single sign-on settings page in Barco Management Suite:
    1. For Discovery URI enter "https://login.microsoftonline.com/{tenant}/.well-known/openid-configuration" where {tenant} is the domain name of Azure AD tenant or it's GUID identifier (see Microsoft Docs).
    2. Optionally, add your own scopes to the Scope field.
    3. For Client ID, enter the Application ID copied earlier.
    4. For Secret, enter the client secret Value that was saved earlier.
    5. Optionally, change the Claims when you've specified your own before.
    6. Save this configuration by clicking on Save.
  8. Test the Configuration in Barco Management Suite
    Note: Any update or creation of new single sign-on configuration can take up to 30 minutes to propagate across all regions.
    1. When the specified time has passed after updating or creation of the configuration, go to action menu for the configuration and click on Test.
    2. You will be prompted to login on your IDP to test the single sign-on.
    3. After successful sign in, the claims returned are shown on this screen.
    4. If a claim isn’t returned, check the claims mapping match between the IDP and the configuration in BMS.
    5. After successful completion of the test, proceed to assigning your account’s domain(s) in next step.
  9. Activate Single Sign-on settings in Barco Management Suite
    1. For the domain you want to assign this configuration, go to options → Edit Assignment
    2. Select the Configuration by name and click on Save
    3. Finally, for the same domain, go to options → Enable the Single sign-on configuration.

SAML v2.0


  1. Navigate to Azure portal and search for the resource Azure Active Directory.
  2. On this page, go to Manage → Enterprise applications → New application.
    1. Click on Create your own application
    2. Enter any appropriate Name for this application for you to track it by
    3. For the query What are you looking to do with your application?, select option:  Integrate any other application you don’t find in the gallery (Non-gallery)
    4. Click Create.

  3. Navigate to Manage → Single sign-on and select SAML as single sign-on method.
    1. You will now be taken to setup page for Single Sign-on with SAML, from where we will get the metadata file for your application.
    2. Use the SAML endpoints for Basic configuration:
    3. Click Save.

       

  4. Add/modify attributes in the Attributes & Claims section only if: 
    1. The Email is not the User principal name for the users in your tenant.
    2. The First name or Last name is not populated for the users in your tenant
  5. Go to section SAML Certificates
    1. Edit → Select Signing Option and change it to Sign SAML Response and Assertion and click Save.

    2. Download Federation Metadata XML.


  6. Go to the Single Sign-on settings page on Barco Management Suite
    1. Click on Add Configuration
    2. Enter a name for the configuration and Select protocol as SAML v2.0
    3. Optionally, change the Assertions for Email, First name or Last name.
     

    Email 

    assertionSubjectName 

    This keyword signals Barco to pick the email from the Subject of the SAML Response. Change it only when the Email is not coming in the UPN

    First name 

    http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname 

     

    Last name 

    http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname 

     

     
    • For Your metadata, select the federation metadata file obtained from your IDP & click Upload.
    • Set the Signing algorithm under SAML certificate, according to the configuration on your IDP.
    • After the metadata has been uploaded, download the Barco metadata file by clicking the download button

    Note: If the Barco metadata doesn’t start downloading, you may need to check your browser settings.

  7. Navigate back to Azure portal tab on the setup Single sign-on page:
    1. Click on Upload metadata file → Select file → Add.
    2. After the metadata file uploaded successfully, click on Save.

     

  8. Test the Configuration in Barco Management Suite
    Note: Any update or creation of new single sign-on configuration can take up to 30 minutes to propagate across all regions.

    1. When the specified time has passed after updating or creation of the configuration, go to action menu for the configuration and click on Test.
    2. You will be prompted to login on your IDP to test the single sign-on.
    3. After successful sign in, the claims returned are shown on this screen.
    4. If a claim isn’t returned, check the claims mapping match between the IDP and the configuration in BMS.
    5. After successful completion of the test, proceed to assigning your account’s domain(s) in next step.
  9. Activate Single Sign-on settings in Barco Management Suite.
    1. For the domain you want to assign this configuration, go to options → Edit Assignment
    2. Select the Configuration by name and click on Save
    3. Finally, for the same domain, go to options → Enable the Single sign-on configuration 

Manage which users can access this SSO configuration


Azure AD allows an option to prevent everyone from signing in to an application by requiring user assignment (see Microsoft Docs).

You can make changes to this by following these steps:

  1. Go to Enterprise applications, and then search for and select the application you have created for this SSO.
  2. To give access to all users, turn off user assignment:
    1. Under Manage, go to Properties.
    2. Set option Assignment required to No and click Save.

      image.png

  1. To give access to specific users, turn on user assignment:
    1. Under Manage, go to Properties.
    2. Set option Assignment required to Yes and click Save.

      image.png

    3. Now you can assign specific users by going to the Users and groups page and selecting Add user/group (see Microsoft Docs).

      image.png

 

Properties

Last updated Aug 23, 2026

No solution found?

Phone support

Our helpdesk provides you with prompt phone support. A team of experienced support engineers is at your service for any professional assistance.